cvestatisticsvulnerability-trendscvss

OpenCVE - CVE Statistics

Provides macro-level statistics on the accelerating volume of vulnerabilities and the slow adoption of modern CVSS scoring standards.

Summary

As of the start of 2025, the CVE ecosystem contains over 275,405 records, with the annual publication rate growing by 14.1% in the last year (reaching 33,206 new vulnerabilities in 2024). Adoption of the latest CVSS 4.0 standard remains extremely low at only 0.91% (~3,600 CVEs), while the legacy CVSS 2.0 standard still accounts for 46.98% of all scored vulnerabilities. High-usage infrastructure components like Enterprise Linux, Debian, and the Linux Kernel are the most frequently impacted products. Major vendors including Microsoft, Red Hat, and Google top the list for reported CVEs, highlighting the systemic importance of their security practices for the broader digital supply chain.

Gaps Analysis

Evidence

Approximately 3,600 CVEs are scored using CVSS 4.0, representing just 0.91% of all CVEs. In comparison, CVSS 2.0 accounts for 46.98%.

Blind Spot

Risk Guard does not explicitly distinguish between the 'Precision' of different CVSS versions, potentially over-weighting legacy CVSS 2.0 scores.

Actionable Capability

Risk Guard would be better if it adjusted risk weights based on the 'CVSS Version Confidence', giving higher precedence to modern 3.1/4.0 scores.

← Previous Next →